CVE-2023-45681: GHSL-2023-145_GHSL-2023-151/GHSL-2023-165_GHSL-2023-172: Several memory access violations in stb_image and stb_vorbis
stbimage.h and stbvorbis libraries contain several memory access violations of different severity.
Other sources
stbvorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory write past an allocated heap buffer in startdecoder. The root cause is a potential integer overflow in sizeof(char) (f->commentlistlength) which may make setupmalloc allocate less memory than required. Since there is another integer overflow an attacker may overflow it too to force setupmalloc to return 0 and make the exploit more reliable. This issue may lead to code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45681?
CVE-2023-45681 is a vulnerability in the stb_vorbis library that allows a crafted file to trigger a memory write beyond the allocated heap buffer.
How severe is CVE-2023-45681?
CVE-2023-45681 has a severity value of 7.3, which is considered high.
What is the root cause of CVE-2023-45681?
The root cause of CVE-2023-45681 is a potential integer overflow in the sizeof(char*) * (f->comment_list_length) calculation, which can lead to memory write beyond the allocated heap buffer.
How can I fix CVE-2023-45681?
To fix CVE-2023-45681, it is recommended to update to a patched version of the stb_vorbis library when available.
Are there any references for CVE-2023-45681?
Yes, you can find more information about CVE-2023-45681 in the following references: [Reference 1](https://securitylab.github.com/advisories/GHSL-2023-145_GHSL-2023-151_stb_image_h/) and [Reference 2](https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_vorbis.c#L3660-L3677).